Document Access Control via User Relationship Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In online conferences, sharing documents with all attendees raises information security concerns, as unrestricted access allows all users to manipulate documents, leading to potential misuse and security issues.

Innovation Solution

A document-usage control apparatus that registers relationship information between users and controls document access based on these relationships, allowing or restricting access based on direct or indirect connections to the organizer, thereby defining a sharing range separate from the attendance range.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a document is disclosed across the board to all users who attend an online conference, then the ease of operation is improved, but information security deteriorates

Engineering Contradiction:
Improvedocument sharing easeVSAvoidinformation security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the user group into different categories based on their relationship to the organizer (e.g., direct subordinates, indirect subordinates, external users). Document sharing permissions are then assigned to each segment independently, allowing the organizer to control which segments can access the document. This resolves the contradiction by maintaining ease of operation for authorized segments while preventing unauthorized access to protect information security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different access control policies to different user segments rather than applying a uniform policy to all users. Each segment receives appropriate document access rights based on their specific relationship to the organizer and the sensitivity requirements of the document. This allows easy access for trusted segments while maintaining security for sensitive documents, resolving the contradiction between ease of operation and information security.

Inventive Principle:
Principle #3Local quality

2Ease of operation

If all users across the board are allowed to manipulate a document, then the ease of operation is improved, but information security deteriorates

Engineering Contradiction:
Improvedocument manipulation easeVSAvoidinformation security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments manipulation permissions by user segment and document type. Different segments (e.g., direct subordinates vs. external users) are granted different levels of manipulation rights based on their relationship to the organizer. This allows easy manipulation for authorized segments while preventing unauthorized manipulation to protect information security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies differentiated manipulation permissions to different user segments rather than uniform access. Each segment receives manipulation rights appropriate to their trust level and the document's sensitivity requirements, enabling easy operation for trusted users while maintaining security controls for sensitive documents.

Inventive Principle:
Principle #3Local quality

3Reliability

If document access is restricted based on user relationships, then information security is improved, but device complexity increases

Engineering Contradiction:
Improveinformation securityVSAvoidaccess control complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary relationship information database that stores pre-defined relationship data between users and organizers. This intermediary structure simplifies the access control logic by providing a ready-reference source for determining user segments, reducing the complexity of real-time relationship analysis while maintaining security-based access control.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent performs preliminary classification of users into segments based on their relationships with the organizer before document access decisions are made. Relationship information is pre-processed and stored, allowing the system to quickly determine appropriate access rights without complex real-time calculations, thus improving security while minimizing added complexity.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11968057B2Document-usage control apparatus, non-transitory computer readable medium, and online conference system
Publication Date: 2024.04.23 FUJIFILM BUSINESS INNOVATION CORP
  • US11968057B2 patent drawing
  • US11968057B2 patent drawing
  • US11968057B2 patent drawing

AI summary

A document-usage control apparatus includes a memory in which a piece of relationship information is registered for each pair of users, the piece of relationship information indicating a relationship between the pair of users, and a processor configured to control use of a document to be shared at an online conference for each user attending the online conference, the use being controlled based on one or more pieces of relationship information registered in the memory.